MALICIOUS — 81d6a4_632c332ec1aa4b95b64be405021ed0f4.pdf
MALICIOUS — 81d6a4_632c332ec1aa4b95b64be405021ed0f4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
dc0d6b457bd17aad5fa5c082e5d43453a3ad76473338f479034ad68370ab254e - SHA-1:
5005be9fef561965b34da256202ac2707bac6f21 - MD5:
e183cb624ce22b9daa666d0a51ca8140 - ssdeep:
768:ZgGzpDiULMnGHTX2a/skUUpfjRenXWtu7hcUihAtC4e5RntVWy2:aGFWU7TX2a1Fhj0Iu7hcVhV5ltVWH - TLSH:
T1F9328DF70097DD9C3AC6AB036DEB115C6086D7886232966499C8776CC47C2BCAF50A70 - Submitted as: 81d6a4_632c332ec1aa4b95b64be405021ed0f4.pdf
- File type: pdf · Size: 45996 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.com/wix?keyword=pokemon+go+mod+apk+file, https://c6b505b6-4125-4975-aab1-85371b061e24.filesusr.com/ugd/d43733_e1a1bcaeab574f56bb12020ef8bed608.pdf?index=true, https://3ad1211b-3e2b-4318-af75-021e0e2897f9.filesusr.com/ugd/3be48b_823f4874d3a449549ad74706f2e9ce1f.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=pokemon+go+mod+apk+file
- https://c6b505b6-4125-4975-aab1-85371b061e24.filesusr.com/ugd/d43733_e1a1bcaeab574f56bb12020ef8bed608.pdf?index=true
- https://3ad1211b-3e2b-4318-af75-021e0e2897f9.filesusr.com/ugd/3be48b_823f4874d3a449549ad74706f2e9ce1f.pdf?index=true
- https://b1b59996-6109-44fe-8a83-3961ecbe3ed4.filesusr.com/ugd/7f614e_302201e673d14d72922344efb6da6eb4.pdf?index=true
- https://a6e9a807-5d24-449a-b2f8-bc3b3d92a093.filesusr.com/ugd/c57cae_446fe3ba78c34211aa606125650d4c60.pdf?index=true
- https://25139b70-d51c-4ed8-accb-96d8f7420378.filesusr.com/ugd/035627_de756fd1a33e48cd82c7515cbf32dd2b.pdf?index=true
- https://b0ee8698-cfc6-456f-bef6-a538da77e0bb.filesusr.com/ugd/145364_aa072dcce1a34816a5f57c019f3b31e4.pdf?index=true
- https://5ded3e8b-d2a2-403b-855d-dcf9c725d984.filesusr.com/ugd/65b209_228d8e745bf242bbb946500795959254.pdf?index=true
- https://7a998e66-ecfd-4d0a-bfb3-772d0a28f02c.filesusr.com/ugd/ceb2e8_803989398a34433b8f6dbd9718275c8b.pdf?index=true
- https://dbd3c9c0-900a-4830-9e8a-e2f526370b1e.filesusr.com/ugd/6f5f23_6afaaf19dbd34e149235ecb7f7b9a5ab.pdf?index=true
- http://baxal.jennyginolson.com/uploads/1/3/1/4/131483281/regobul.pdf
- http://files.studio59live.com/uploads/1/3/0/8/130874240/jigifomerajidi.pdf
- https://bddec66a-e2cf-4c74-82f3-c4ccedd95153.filesusr.com/ugd/0af078_f37ae750104545328a322b99b32bb289.pdf?index=true
- https://3c156195-8c8c-44a6-b4db-23ec8e05eddd.filesusr.com/ugd/145364_eb9d26c6759a45fa847d144eb6a8d677.pdf?index=true
- https://dcce8276-1663-4194-a9b9-bda03013eee9.filesusr.com/ugd/3be48b_788020053a734c109c2e174781198636.pdf?index=true
- https://98e6a617-be7b-4871-aa30-b64b413a3a63.filesusr.com/ugd/529dbf_5d18de979ab042f78ab638480315181c.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- c6b505b6-4125-4975-aab1-85371b061e24.filesusr.com
- 3ad1211b-3e2b-4318-af75-021e0e2897f9.filesusr.com
- b1b59996-6109-44fe-8a83-3961ecbe3ed4.filesusr.com
- a6e9a807-5d24-449a-b2f8-bc3b3d92a093.filesusr.com
- 25139b70-d51c-4ed8-accb-96d8f7420378.filesusr.com
- b0ee8698-cfc6-456f-bef6-a538da77e0bb.filesusr.com
- 5ded3e8b-d2a2-403b-855d-dcf9c725d984.filesusr.com
- 7a998e66-ecfd-4d0a-bfb3-772d0a28f02c.filesusr.com
- dbd3c9c0-900a-4830-9e8a-e2f526370b1e.filesusr.com
- baxal.jennyginolson.com
- files.studio59live.com
- bddec66a-e2cf-4c74-82f3-c4ccedd95153.filesusr.com
- 3c156195-8c8c-44a6-b4db-23ec8e05eddd.filesusr.com
- dcce8276-1663-4194-a9b9-bda03013eee9.filesusr.com
- 98e6a617-be7b-4871-aa30-b64b413a3a63.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report